Back to the registry
Agent passport

LEX Risk Management Coach

Lockbase Cyber · Cybersecurity & IT

SaaSNo attestation published

Certification per Microsoft Marketplace.

SOCSecurity CopilotAgentic
Provenance reach4 of 12 layers traced

Evidence tier Source Confirmed · 7 captures on record

User ratingNot rated0 reviews on the listing
Runs onSaaSSaaS
ProvenanceUnknown44% of the provenance layers this product can disclose
Evidence riskHighSign in to see the basis for this band.

What the publisher says

As described on Microsoft Marketplace.

Lockbase Exposure Agent (LEX = Lockbase EXposure) is a pre-breach risk-reduction agent that surfaces standing, reducible escalation-path preconditions across Microsoft Entra ID, on-premises Active Directory, and Azure inside Security Copilot, helping CISOs and security teams find and cut the attack paths an adversary would use before exploitation — rather than waiting for an alert and triaging after the fact.

Inputs: Microsoft Defender Advanced Hunting telemetry (identity, sign-in, audit/CloudAppEvents, Exposure Management graph, vulnerability/TVM, device, and AI-agent tables), Microsoft Graph Secure Score, read-only Microsoft Entra and Intune context, and analyst natural-language prompts (a topic such as "how is my Active Directory environment looking", an account UPN, a service-principal or application name, a device name, or a request for a risk scorecard).

Show the rest of the publisher’s description (8 more lines)

Tasks: Surfaces standing, reducible escalation-path preconditions across identity and high-impact exposure by orchestrating 61 risk-reduction skills (60 Advanced Hunting KQL skills plus one Microsoft Graph Secure Score skill) — Entra application and service-principal attack paths, on-prem Active Directory privileged access and Kerberos/NTLM footprint, standing access to crown-jewel assets (Key Vaults, domain controllers, sensitive storage and SQL, Tier-0 systems), cross-subscription privilege blast radius, sign-in / Conditional Access / MFA gaps, AI-agent identity over-privilege, exploitable vulnerabilities and end-of-life software (with CVE, CVSS, and remote-code-execution context) on internet-facing or crown-jewel assets, mailbox delegation, external mail forwarding, SharePoint/OneDrive sharing exposure, and endpoint supply-chain risk. It maps each scoped question to the right skills, ranks findings P1–P4, down-ranks expected access (Microsoft first-party service principals and by-design Active Directory Tier-0 admin groups) to informational, and routes configuration hygiene to Microsoft Secure Score rather than duplicating it. It is risk reduction, not attack detection, and is not a general CVE catalog.

Outputs: Prioritized (P1–P4) risk findings presented worst-first as structured lists, each with the risk level, the escalation path and why it matters (the BloodHound/AzureHound-style standing edge to cut), and the specific reduction action (right-size, remove, harden, retire, or move to PIM-eligible just-in-time). Findings name the actionable identifiers — Entra object and application IDs, host names, source IPs, and asset names — with the precise access verb (for example "WRITE / OWNER access to a named domain controller" or "MONITORING / LOGGING WRITE to a Key Vault"), and route tenant configuration posture to Microsoft Secure Score.

Lockbase Exposure Agent consumes approximately 0.3–1.5 SCU per run, depending on review depth:

  • A rapid risk scorecard (one token-capped probe per category across the full estate) runs at ~0.3–0.5 SCU.
  • A single-category deep-dive that runs the 5–6 highest-priority skills for one area (for example Entra application attack paths or sign-in/MFA gaps) averages ~0.6–1.0 SCU.
  • A broad, multi-category review, or a deep dive that includes one of the heavier Microsoft Exposure Management graph skills (crown-jewel standing access, cross-subscription blast radius, inherited or group-inherited access), reaches ~1.0–1.5 SCU.
  • An exposure-graph skill that scans the full identity/resource graph adds ~0.2 SCU per skill beyond the lightweight behavioral and sign-in queries.
  • SCU consumption scales with the number of skills invoked, how many risk categories are deep-dived, and the size of the Exposure Management graph and Advanced Hunting tables scanned during each run.

Preview

5 images
LEX Risk Management Coach preview 1LEX Risk Management Coach preview 2LEX Risk Management Coach preview 3LEX Risk Management Coach preview 4LEX Risk Management Coach preview 5

Agent build and provenance

See the full provenance

The layer-by-layer build, the evidence behind each claim, the risk basis and the cross-marketplace links are open to any account. Some rows are disclosed, some the source leaves Unknown; a free account shows you which.

Compliance

Government
  • FedRAMPConfirmedNot listed90%, registry-checkedNo FedRAMP Marketplace entry matched this vendor's domain, checked 2026-08-27registry recordas observed 2026-08-27

Confirmed means matched to a public authoritative registry. Claimed means the vendor or its listing states it, not yet cross-checked. A framework not shown was not found in any source we hold, which is not evidence against it. Not listed means a scoped registry check found no match for this vendor's domain: a No is a scoped registry check, not a compliance judgment. Confidence bands: 95% domain-verified, 90% registry-checked, 80% self-attested, 70% weak signal. Self-attested items marked “vendor's site” are gathered from the vendor's own website and are not verified by us.

Plans and pricing as listed

1 listed
lex_plan_per_organization
First month free, then $10,000.00/month
LEX Agent is licensed per organization. A single subscription covers all users in your tenant who interact with the agent through Microsoft Security Copilot — no per-seat counting, no user limits.

Sources

Marketplace listingmarketplace.microsoft.comSource
Privacy PolicyPrivacy PolicySource

Publisher resources

2 links
Lex Agent Capabilities agents.lockbasecyber.comSource

Linked repositories

RepositoriesUnknownUnknown

Unknown means this listing does not publish a repository. It is not a statement that the code is closed, and a linked repository is not a claim that the publisher wrote it: the registry computes that relationship privately and does not publish it.

Pricing
Paid
1 plan listed
Delivery
SaaS
https://lockbasecyber.com/contact-us/
Open the source listing ↗

Evidence risk is the share of the build you cannot see before you deploy, not a security rating. Sign in to see the layer-by-layer basis for this band.